EP3127038B1 - Verfahren und system zum schutz und/oder zur anonymisierung einer benutzeridentität und/oder von benutzerdaten eines teilnehmers eines datenschutzdienstes, mobiles kommunikationsnetzwerk, programm und computerprogrammprodukt - Google Patents
Verfahren und system zum schutz und/oder zur anonymisierung einer benutzeridentität und/oder von benutzerdaten eines teilnehmers eines datenschutzdienstes, mobiles kommunikationsnetzwerk, programm und computerprogrammprodukt Download PDFInfo
- Publication number
- EP3127038B1 EP3127038B1 EP15709644.7A EP15709644A EP3127038B1 EP 3127038 B1 EP3127038 B1 EP 3127038B1 EP 15709644 A EP15709644 A EP 15709644A EP 3127038 B1 EP3127038 B1 EP 3127038B1
- Authority
- EP
- European Patent Office
- Prior art keywords
- user
- data
- party service
- computing device
- user identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/02—Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
- G06F21/6254—Protecting personal data, e.g. for financial or medical purposes by anonymising data, e.g. decorrelating personal data from the owner's identification
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0407—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the identity of one or more communicating identities is hidden
- H04L63/0421—Anonymous communication, i.e. the party's identifiers are hidden from the other party or parties, e.g. using an anonymizer
Definitions
- the present invention relates to a method for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service.
- the present invention relates to a system for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service.
- the present invention relates to a mobile communication network suitable for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service.
- Some third party services e.g. so called context-aware services, typically use contextual elements to learn about a user's behaviour and situation, wherein smart recommendations may be provided to the user. For example, a service may ask to access email and other user data in order to act as a personal assistant. However, the third party services require personal information of the user in order to provide the service targeted to the user. Thus, the privacy protection of the user is relatively low because personal information may be misused or sold to other organizations by the companies associated with the third party services.
- US 2014/0059693 A1 discloses a method for managing privacy of personal bank account information which involves associating shipping identifier with a user identifier, where the address information of an anonymous user is obtained from a shipping entity.
- An object of the present invention is to provide a method, a system and a mobile communication network for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service such that the user-convenience is improved with regard to third party services being provided via the telecommunications network.
- the object of the present invention is achieved by a method for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service, wherein the data protection service is accessed, via a telecommunications network, by means of a computing device of the subscriber of the data protection service, the computing device being connected to the telecommunications network, wherein in case that a third party service is accessed by the computing device via the telecommunications network, the third party service receives user related data, the user related data being data related to the user identity and/or user data, wherein accessing the third party service via the data protection service involves a transmission of the user related data such that the user identity and/or the user data are at least partly protected and/or anonymized with respect to the third party service
- third party services which typically require a user's identity and/or user data (personal data) - such that the user-convenience is improved, in particular with regard to information security and/or privacy protection.
- the information security is improved with regard to user data and/or user identity because third party services may be used either without or only by partly providing the user data and/or user identity (in form of the user related data) to the third party service. Misuse of the personal information by a third party is thereby advantageously inhibited or at least restrained.
- the data protection service is therefore also called a trusted provider.
- the third party service is a payment service, an application service or electronic commerce service.
- the user related data comprise the plaintext of the user identity and/or user data
- the transmission to the third party service is either avoided or the user related data are modified data with respect to the second part of the user identity and/or user data.
- the data protection service shares the first part (of the user identity and/or user data) openly and the second part (of the user identity and/or user data) in a protected format with the third party service.
- the user identity and/or user data are completely protected and/or anonymized with respect to the third party service
- the data protection service shares all data in a protected format with the third party service.
- At least a first or a second security level is selected by the subscriber of the computing device with regard to the access to the third party service to the user related data.
- the first security level concierge level
- the user identity and/or user data are completely protected and/or anonymized with respect to the third party service.
- the second security level protected level
- only a part of the user identity and/or user data is protected and/or anonymized with respect to the third party service.
- the telecommunications network is a mobile communication network
- the computing device is a mobile computing device, especially a mobile phone, a smart phone, a tablet computer, or another portable computing device.
- the third party service is an application provided to the computing device, wherein the application is executed on the computing device or on a network node of the telecommunications network, wherein by accessing the third party service via the data protection service the behaviour of the application is modified regarding the transmission of the user related data such that the user identity and/or the user data are at least partly protected and/or anonymized with respect to the third party service.
- the behaviour of the application is modified by means of applying a response and/or permission approach.
- the behaviour of the application is modified depending on a response and/or permission method being carried out.
- the data protection service comprises a response system for carrying out the response method, wherein the third party service transmits a request message to the response system, the request message being configured to request for user data and/or user identity associated with the subscriber of the data protection service, wherein the response system transmits a response message in response to the request message, wherein the response message comprises the user related data such that the user identity and/or the user data are at least partly protected and/or anonymized with respect to the third party service.
- the user related data are configured such that the third party service receives the requested information without sharing the core profile data of the subscriber.
- the user data may be related to a birthday of the subscriber.
- the response message may comprise the user related data in the form of a date, e.g. May 20th, rather than the date of birth.
- the data protection service is configured such that the subscriber may register or login with the data protection service using the computing device.
- the data protection service provides a login interface for the subscriber.
- the login interface is a graphical user interface comprising an icon, e.g. a TrustMe icon, to be used for login.
- a user account is generated for the subscriber, wherein personal details and/or other configuration details are stored such that the subscriber does not need to enter in the user identity and/or user data each time when the subscriber logs in to the data protection service. It is thereby advantageously possible to improve the user convenience, in particular with respect to the transmission of the user related data to the third party service.
- the method comprises anonymizing the user identity and the user data such that, by analysing the user related data transmitted to the third party service, the user identity associated with the computing device is hidden.
- the present invention it is thereby advantageously possible to protect and/or anonymize the user identity and/or user data of the subscriber of the data protection service such that the user-convenience is improved with regard to the access of third party services provided via the telecommunications network.
- the present invention also relates to a system for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service, the system comprising the data protection service, a telecommunications network, and a computing device, wherein the system is configured such that the data protection service is accessed, via the telecommunications network, by means of the computing device of the subscriber of the data protection service, the computing device being connected to the telecommunications network, wherein the system is configured such that in case that a third party service is accessed by the computing device via the telecommunications network, the third party service receives user related data, the user related data being data related to the user identity and/or user data, wherein the system is configured such that accessing the third party service via the data protection service involves a transmission of the user related data such that the user identity and/or the user data are at least partly protected and/or anonymized with respect to the third party service
- the present invention it is thereby advantageously possible to protect and/or anonymize the user identity and/or user data of the subscriber of a data protection service such that the user-convenience is improved with regard to the access of third party services provided via the telecommunications network. In particular, misuse of personal data is inhibited.
- the system allows the subscriber to use third party services that require the use of the user related data under improved information security conditions.
- the system is configured such that for a first part of the user identity and/or user data, the user related data comprise the plaintext of the user identity and/or user data, and wherein the system is configured such that for a second part of the user identity and/or user data, the transmission to the third party service is either avoided or the user related data are modified data with respect to the second part of the user identity and/or user data.
- the present invention it is thereby advantageously possible to provide the user related data to the third party service such that the third party service receives only the first part of the user data and/or user identity in plaintext. Thereby, a second security level (protected level) is realized.
- the system is configured such that the user identity and/or user data are completely protected and/or anonymized with respect to the third party service
- the present invention it is thereby advantageously possible to provide the user related data to the third party service such that the third party service receives the complete user data and/or user identity in a secured way.
- a first security level (concierge level) is realized.
- the telecommunications network is a mobile communication network
- the computing device is a mobile computing device, especially a mobile phone, a smart phone, a tablet computer, or another portable computing device.
- the present invention relates to a mobile communication network suitable for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service in a system according to the present invention.
- the present invention relates to a program comprising a computer readable program code which, when executed on a computer or on a computing device or on a network component of a telecommunications network or in part on a computing device and in part on a network component of a telecommunications network, causes the computer or the computing device and/or the network component of the telecommunications network to perform a method according to the present invention.
- the present invention relates to a computer program product for using a machine type communication device with a telecommunications network
- the computer program product comprising a computer program stored on a storage medium
- the computer program comprising program code which, when executed on a computer or on a computing device or on a network component of a telecommunications network or in part on a computing device and in part on a network component of a telecommunications network, causes the computer or the computing device and/or the network component of the telecommunications network to perform a method according to the present invention.
- Figure 1 schematically illustrates a system according to the present invention.
- FIG. 1 a system according to the present invention is illustrated schematically.
- the system is configured for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service 200.
- the system comprises the data protection service 200, a telecommunications network 100, and a computing device 20.
- the telecommunications network 100 is preferably an Internet Protocol (IP) based telecommunications network 100.
- IP Internet Protocol
- the telecommunications network 100 may include any landline and/or mobile computer network, for example the Internet and/or any telephone network.
- the computing device 20 is a computing device of the subscriber of the data protection service 200.
- the computing device 20 is connected to the telecommunications network 100.
- the computing device 20 is preferably a personal computer or mobile computer, for example a tablet computer or smartphone or any other computing device.
- the system is configured such that the data protection service 200 is accessed, via the telecommunications network 100, by means of the computing device 20 of the subscriber of the data protection service 200.
- the subscriber - which is herein also called a user of the computing device 20 - is registered with the data protection service 200, wherein a personal account is set-up for the user.
- the data protection service 200 is configured to create a digital passport depending on user data and/or user identity (personal data) and further depending on authorization information of the user.
- the user provides the authorization information (e.g. a permission or level of access) for the third party service 300.
- the digital passport is controlled by the user of the computing device 20 and may be updated over time.
- the system is configured such that in case that a third party service 300 is accessed by the computing device 20 via the telecommunications network 100, the third party service 300 receives user related data.
- the user related data are data related to the user identity and/or user data.
- the user data and/or user identity includes, for example, at least one of the following: name, home address, work address, date of birth, sex, marital status, family details, health details, social network details, email details, calendar/contacts details, bank details, other service provider details e.g. airlines, insurance companies, ecommerce companies, location, devices, personal preferences (profile), internet favorites/bookmarks and usage, safety preferences. It will also be possible to store the digital identity of the subscriber.
- the data protection service 200 is configured such that user identity and/or user data may be added to the digital passport, e.g. in the form of data fields.
- one or more data fields are specified either by the third party service 300 (in case a data element is required which data element is not yet comprised by the digital passport) or the one or more data fields are entered by the user.
- the data protection service 200 is accessible from any computing device 20 connected to the telecommunications network 100.
- the data protection service 200 comprises an application interface for communication with a developer of a third party service 300.
- the application interface is configured to connect the third party service 300 (e.g. any application or internet service) to the data protection service 200 such that the third party service 300 is certified as linked to the data protection service 200.
- the data protection service is configured to allow or deny access to third party services. Thereby, it is advantageously possible to exclude illegal or blacklisted services.
- the system is configured such that accessing the third party service 300 via the data protection service 200 involves a transmission of the user related data such that the user identity and/or the user data are at least partly protected and/or anonymized with respect to the third party service 300 by means of at least partly avoiding the transmission of the plaintext of the user identity and/or the user data to the third party service 300.
- the system is configured such that accessing the third party service 300 via the data protection service 200 involves a transmission of the user related data such that the user identity and/or the user data are at least partly protected and/or anonymized with respect to the third party service 300 by means of the user related data - transmitted to the third party service 300 - being modified data with respect to the user identity and/or user data of the subscriber.
- modified data means that any direct association of the subscriber to the user data and/or user identity is removed, wherein the user related data is provided in a form that can be used by the third party service.
- the subscriber is thereby enabled to control whether the user data and/or user identity is shared with a third party service 300.
- the subscriber is enabled to configure the data protection service 200 such that the user data and/or user identity are at least partly shared openly or at least partly shared securely.
- the user related data are generated depending on the user data and/or user identity by using a request based method, a protected identity method and/or a permission based method.
- the third party service 300 requests user related data, the user related data being requested from the data protection service 200, e.g. via the application interface.
- the data protection service 200 requests, depending on the request of the user related data by the third party service, from the subscriber at the computing device 20 authorization information related to the third party service 300.
- the user related data comprises an identifier (ID), wherein the ID is related to the subscriber, wherein the relationship between the subscriber and the ID is a trusted relationship existing (only) within the data protection service 200.
- ID is provided to the third party service 300 in a fraudulent way, i.e. without any possibility for the third party service to know the true identity of the subscriber (user identity).
- the ID is a randomly generated digital identity, which is, in particular, generated for each session separately.
- the ID is only unique to the subscriber once per session with the third party service 300 (as it changes each time).
- the subscriber is enabled to assign at least one piece of authorization information (e.g. permissions) per third party service 300 and, in particular, per data the subscriber wishes to use for a selected third party service 300.
- the subscriber is enabled to allow different degrees of privacy or security levels. For example, personal data may be shared for payment services but not for unknown third party services 300.
- the data protection service 200 protects (e.g. excludes or hides) - with regard to the third party service 300 - at least first information (and optionally second and/or third information) of the user data and/or user identity.
- the data protection service 200 protects at least second information (and optionally third information) of the user data and/or user identity.
- the data protection service 200 (only) protects third information of the user data and/or user identity.
- the first information relates to at least one of credit card details, bank account details, passport details, national insurance and/or other personal details a customer rarely gives out only in a trusted environment.
- the second information relates to at least one of date of birth, email login, social network login and/or other useful sites/passwords.
- the third information relates to first name, surname, address, email address, marital status, male/female, age and/or other personal details a subscriber usually gives out on a frequent basis to websites.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- Databases & Information Systems (AREA)
- Medical Informatics (AREA)
- Computing Systems (AREA)
- Telephonic Communication Services (AREA)
- Mobile Radio Communication Systems (AREA)
- Information Transfer Between Computers (AREA)
- Telephone Function (AREA)
Claims (13)
- Verfahren zum Schützen und/oder Anonymisieren einer Benutzeridentität und/oder von Benutzerdaten eines Abonnenten eines Datenschutzdienstes (200),
wobei der Zugriff auf den Datenschutzdienst (200) über ein Telekommunikationsnetz (100) mit Hilfe einer Computervorrichtung (20) des Abonnenten des Datenschutzdienstes (200) erfolgt, wobei die Computervorrichtung (20) mit dem Telekommunikationsnetz (100) verbunden ist,
wobei für den Fall, dass durch die Computervorrichtung (20) über das Telekommunikationsnetz (100) auf einen Drittdienst (300) zugegriffen wird, der Drittdienst (300) benutzerbezogene Daten empfängt, wobei die benutzerbezogenen Daten Daten sind, die sich auf die Benutzeridentität und/oder auf Benutzerdaten beziehen, wobei der Zugriff auf den Drittdienst (300) über den Datenschutzdienst (200) eine Übertragung der benutzerbezogenen Daten umfasst, dergestalt, dass die Benutzeridentität und/oder die Benutzerdaten mindestens teilweise mit Bezug auf den Drittdienst (300) geschützt und/oder anonymisiert werden:- durch mindestens teilweises Vermeiden der Übertragung des Klartextes der Benutzeridentität und/oder der Benutzerdaten an den Drittdienst (300) oder- indem die benutzerbezogenen Daten - die an den Drittdienst (300) übermittelt werden - modifizierte Daten mit Bezug auf die Benutzeridentität und/oder die Benutzerdaten des Abonnenten sind,dadurch gekennzeichnet, dass der Datenschutzdienst (200) einen digitalen Pass in Abhängigkeit von der Benutzeridentität und/oder den Benutzerdaten des Abonnenten und des Weiteren in Abhängigkeit von Autorisierungsinformationen des Abonnenten erzeugt, wobei der Abonnent die Autorisierungsinformationen für den Drittdienst (300) bereitstellt. - Verfahren nach Anspruch 1, wobei für einen ersten Teil der Benutzeridentität und/oder der Benutzerdaten die benutzerbezogenen Daten den Klartext der Benutzeridentität und/oder der Benutzerdaten umfassen, und wobei für einen zweiten Teil der Benutzeridentität und/oder der Benutzerdaten die Übertragung an den Drittdienst (300) entweder vermieden wird, oder die benutzerbezogenen Daten modifizierte Daten mit Bezug auf den zweiten Teil der Benutzeridentität und/oder der Benutzerdaten sind.
- Verfahren nach Anspruch 1, wobei die Benutzeridentität und/oder die Benutzerdaten mit Bezug auf den Drittdienst (300) vollständig geschützt und/oder anonymisiert werden;- durch mindestens teilweises Vermeiden der Übertragung des Klartextes der Benutzeridentität und/oder der Benutzerdaten an den Drittdienst (300) oder- indem die benutzerbezogenen Daten - die an den Drittdienst (300) übermittelt werden - modifizierte Daten mit Bezug auf die Benutzeridentität und/oder die Benutzerdaten des Abonnenten sind.
- Verfahren nach einem der vorangehenden Ansprüche, wobei das Telekommunikationsnetz (100) ein mobiles Kommunikationsnetz ist und die Computervorrichtung (20) eine mobile Computervorrichtung, insbesondere ein Mobiltelefon, ein Smartphone, ein Tablet-Computer oder eine andere portable Computervorrichtung, ist.
- Verfahren nach einem der vorhergehenden Ansprüche, wobei der Drittdienst (300) eine Anwendung ist, die der Computervorrichtung (20) zur Verfügung gestellt wird, wobei die Anwendung auf der Computervorrichtung (20) oder auf einem Netzknoten des Telekommunikationsnetzes (100) ausgeführt wird, wobei durch den Zugriff auf den Drittdienst (300) über den Datenschutzdienst (200) das Verhalten der Anwendung hinsichtlich der Übertragung der benutzerbezogenen Daten so modifiziert wird, dass die Benutzeridentität und/oder die Benutzerdaten mindestens teilweise mit Bezug auf den Drittdienst (300) geschützt und/oder anonymisiert werden.
- Verfahren nach einem der vorhergehenden Ansprüche, wobei das Verfahren das Anonymisieren der Benutzeridentität und der Benutzerdaten in einer solchen Weise umfasst, dass durch die Analyse der an den Drittdienst (300) übertragenen benutzerbezogenen Daten die mit der Computervorrichtung (20) verknüpfte Benutzeridentität verborgen wird.
- System zum Schützen und/oder Anonymisieren einer Benutzeridentität und/oder von Benutzerdaten eines Abonnenten eines Datenschutzdienstes (200), wobei das System den Datenschutzdienst (200), ein Telekommunikationsnetz (100) und eine Computervorrichtung (20) umfasst,
wobei das System so eingerichtet ist, dass der Zugriff auf den Datenschutzdienst (200) über das Telekommunikationsnetz (100) mit Hilfe der Computervorrichtung (20) des Abonnenten des Datenschutzdienstes (200) erfolgt, wobei die Computervorrichtung (20) mit dem Telekommunikationsnetz (100) verbunden ist,
wobei das System so eingerichtet ist, dass für den Fall, dass durch die Computervorrichtung (20) über das Telekommunikationsnetz (100) auf einen Drittdienst (300) zugegriffen wird, der Drittdienst (300) benutzerbezogene Daten empfängt, wobei die benutzerbezogenen Daten Daten sind, die sich auf die Benutzeridentität und/oder auf Benutzerdaten beziehen, wobei das System so eingerichtet ist, dass der Zugriff auf den Drittdienst (300) über den Datenschutzdienst (200) eine Übertragung der benutzerbezogenen Daten umfasst, dergestalt, dass die Benutzeridentität und/oder die Benutzerdaten mindestens teilweise mit Bezug auf den Drittdienst (300) geschützt und/oder anonymisiert werden:- durch mindestens teilweises Vermeiden der Übertragung des Klartextes der Benutzeridentität und/oder der Benutzerdaten an den Drittdienst (300) oder- indem die benutzerbezogenen Daten - die an den Drittdienst (300) übermittelt werden - modifizierte Daten mit Bezug auf die Benutzeridentität und/oder die Benutzerdaten des Abonnenten sind,dadurch gekennzeichnet, dass der Datenschutzdienst (200) dafür eingerichtet ist, einen digitalen Pass in Abhängigkeit von der Benutzeridentität und/oder den Benutzerdaten des Abonnenten und des Weiteren in Abhängigkeit von Autorisierungsinformationen des Abonnenten zu erzeugen, wobei der Abonnent die Autorisierungsinformationen für den Drittdienst (300) bereitstellt. - System nach Anspruch 7, wobei das System so eingerichtet ist, dass für einen ersten Teil der Benutzeridentität und/oder der Benutzerdaten die benutzerbezogenen Daten den Klartext der Benutzeridentität und/oder der Benutzerdaten umfassen, und wobei das System so eingerichtet ist, dass für einen zweiten Teil der Benutzeridentität und/oder der Benutzerdaten die Übertragung an den Drittdienst (300) entweder vermieden wird, oder die benutzerbezogenen Daten modifizierte Daten mit Bezug auf den zweiten Teil der Benutzeridentität und/oder der Benutzerdaten sind.
- System nach Anspruch 7, wobei das System so eingerichtet ist, dass die Benutzeridentität und/oder die Benutzerdaten mit Bezug auf den Drittdienst (300) vollständig geschützt und/oder anonymisiert werden:- durch mindestens teilweises Vermeiden der Übertragung des Klartextes der Benutzeridentität und/oder der Benutzerdaten an den Drittdienst (300) oder- indem die benutzerbezogenen Daten - die an den Drittdienst (300) übermittelt werden - modifizierte Daten mit Bezug auf die Benutzeridentität und/oder die Benutzerdaten des Abonnenten sind.
- System nach einem der Ansprüche 7 bis 9, wobei das Telekommunikationsnetz (100) ein mobiles Kommunikationsnetz ist und die Computervorrichtung (20) eine mobile Computervorrichtung, insbesondere ein Mobiltelefon, ein Smartphone, ein Tablet-Computer oder eine andere portable Computervorrichtung, ist.
- Mobiles Kommunikationsnetz (100), das dafür geeignet ist, eine Benutzeridentität und/oder Benutzerdaten eines Abonnenten eines Datenschutzdienstes (200) in einem System nach einem der Ansprüche 7 bis 10 zu schützen und/oder zu anonymisieren.
- Programm, das einen computerlesbaren Programmcode umfasst, der, wenn er auf einem Computer oder auf einer Computervorrichtung (20) oder auf einer Netzkomponente eines Telekommunikationsnetzes (100) oder teilweise auf einer Computervorrichtung (20) und teilweise auf einer Netzkomponente eines Telekommunikationsnetzes (100) ausgeführt wird, den Computer oder die Computervorrichtung (20) und/oder die Netzkomponente des Telekommunikationsnetzes (100) veranlasst, ein Verfahren nach einem der Ansprüche 1 bis 6 auszuführen.
- Computerprogrammprodukt zur Verwendung einer Kommunikationsvorrichtung (20) vom Maschinentyp mit einem Telekommunikationsnetz (100), wobei das Computerprogrammprodukt ein auf einem Speichermedium gespeichertes Computerprogramm umfasst, wobei das Computerprogramm Programmcode umfasst, der, wenn er auf einem Computer oder auf einer Computervorrichtung (20) oder auf einer Netzkomponente eines Telekommunikationsnetzes (100) oder teilweise auf einer Computervorrichtung (20) und teilweise auf einer Netzkomponente eines Telekommunikationsnetzes (100) ausgeführt wird, den Computer oder die Computervorrichtung (20) und/oder die Netzkomponente des Telekommunikationsnetzes (100) veranlasst, ein Verfahren nach einem der Ansprüche 1 bis 6 auszuführen.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PL15709644T PL3127038T3 (pl) | 2014-03-31 | 2015-03-03 | Sposób i system ochrony i/lub anonimizacji tożsamości użytkownika i/lub danych użytkownika abonenta usługi ochrony danych, sieć komunikacji mobilnej, program i produkt programu komputerowego |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP14162870 | 2014-03-31 | ||
| PCT/EP2015/054370 WO2015150006A1 (en) | 2014-03-31 | 2015-03-03 | Method and system for protecting and/or anonymizing a user identity and/or user data of a subscriber of a data protection service, mobile communication network, program and computer program product |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP3127038A1 EP3127038A1 (de) | 2017-02-08 |
| EP3127038B1 true EP3127038B1 (de) | 2020-04-29 |
Family
ID=50442359
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP15709644.7A Active EP3127038B1 (de) | 2014-03-31 | 2015-03-03 | Verfahren und system zum schutz und/oder zur anonymisierung einer benutzeridentität und/oder von benutzerdaten eines teilnehmers eines datenschutzdienstes, mobiles kommunikationsnetzwerk, programm und computerprogrammprodukt |
Country Status (9)
| Country | Link |
|---|---|
| US (1) | US20170171744A1 (de) |
| EP (1) | EP3127038B1 (de) |
| JP (1) | JP6568869B2 (de) |
| KR (1) | KR101856455B1 (de) |
| CN (1) | CN106416188B (de) |
| ES (1) | ES2800900T3 (de) |
| IL (1) | IL247848B (de) |
| PL (1) | PL3127038T3 (de) |
| WO (1) | WO2015150006A1 (de) |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20230145741A1 (en) * | 2012-09-07 | 2023-05-11 | Mapmyid, Inc. | Address exchange systems and methods |
| JP7018557B2 (ja) * | 2016-12-28 | 2022-02-14 | 高歩 中村 | Bcn(ブロックチェーンネットワーク)を使用したデータ利用方法、システムおよびそのプログラム |
| JP7005102B2 (ja) * | 2017-12-28 | 2022-01-21 | 高歩 中村 | Bcn(ブロックチェーンネットワーク)を使用したデータ利用方法、システムおよびそのプログラム |
| US12229308B1 (en) * | 2022-03-31 | 2025-02-18 | United Services Automobile Association (Usaa) | Systems and methods for sharing user data |
| CN118353605B (zh) * | 2024-06-14 | 2024-08-20 | 长江三峡集团实业发展(北京)有限公司 | 分布式匿名认证方法、装置、系统及存储介质 |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2003100544A2 (en) * | 2002-05-24 | 2003-12-04 | Telefonaktiebolaget Lm Ericsson (Publ) | Method for authenticating a user to a service of a service provider |
| JP2005301691A (ja) * | 2004-04-12 | 2005-10-27 | Infocity Inc | 個人情報出力装置および方法 |
| JP2006301831A (ja) * | 2005-04-19 | 2006-11-02 | National Institute Of Advanced Industrial & Technology | 管理装置 |
| WO2007047310A2 (en) * | 2005-10-12 | 2007-04-26 | Prefpass Inc. | System and method for the reversible leasing of anonymous user data in exchange for personalized content including targeted advertisements |
| JP4677348B2 (ja) * | 2006-01-12 | 2011-04-27 | 富士通株式会社 | 個人情報収集装置、個人情報提供システムおよび個人情報提供方法 |
| JP5796574B2 (ja) * | 2010-05-10 | 2015-10-21 | 日本電気株式会社 | 情報処理装置、制御方法及びプログラム |
| CN103023856B (zh) * | 2011-09-20 | 2018-07-13 | 中兴通讯股份有限公司 | 单点登录的方法、系统和信息处理方法、系统 |
| JP2013088994A (ja) * | 2011-10-18 | 2013-05-13 | Sony Corp | 情報処理装置、サーバ、情報処理システム、および情報処理方法 |
| US8718607B2 (en) | 2012-04-12 | 2014-05-06 | At&T Intellectual Property I, L.P. | Anonymous customer reference services enabler |
| US9262623B2 (en) * | 2012-08-22 | 2016-02-16 | Mcafee, Inc. | Anonymous shipment brokering |
| US11030587B2 (en) * | 2014-04-30 | 2021-06-08 | Mastercard International Incorporated | Systems and methods for providing anonymized transaction data to third-parties |
-
2015
- 2015-03-03 WO PCT/EP2015/054370 patent/WO2015150006A1/en not_active Ceased
- 2015-03-03 ES ES15709644T patent/ES2800900T3/es active Active
- 2015-03-03 US US15/300,299 patent/US20170171744A1/en not_active Abandoned
- 2015-03-03 KR KR1020167029976A patent/KR101856455B1/ko active Active
- 2015-03-03 EP EP15709644.7A patent/EP3127038B1/de active Active
- 2015-03-03 PL PL15709644T patent/PL3127038T3/pl unknown
- 2015-03-03 CN CN201580027639.1A patent/CN106416188B/zh active Active
- 2015-03-03 JP JP2016559533A patent/JP6568869B2/ja active Active
-
2016
- 2016-09-15 IL IL247848A patent/IL247848B/en active IP Right Grant
Non-Patent Citations (1)
| Title |
|---|
| None * |
Also Published As
| Publication number | Publication date |
|---|---|
| IL247848B (en) | 2020-10-29 |
| KR20160143706A (ko) | 2016-12-14 |
| PL3127038T3 (pl) | 2020-08-24 |
| CN106416188B (zh) | 2020-11-24 |
| EP3127038A1 (de) | 2017-02-08 |
| ES2800900T3 (es) | 2021-01-05 |
| JP2017513132A (ja) | 2017-05-25 |
| WO2015150006A1 (en) | 2015-10-08 |
| JP6568869B2 (ja) | 2019-08-28 |
| IL247848A0 (en) | 2016-11-30 |
| CN106416188A (zh) | 2017-02-15 |
| KR101856455B1 (ko) | 2018-05-10 |
| US20170171744A1 (en) | 2017-06-15 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11805131B2 (en) | Methods and systems for virtual file storage and encryption | |
| US12256015B2 (en) | Systems and methods for secure remote identity verification | |
| US8819784B2 (en) | Method for managing access to protected resources and delegating authority in a computer network | |
| US9161226B2 (en) | Associating services to perimeters | |
| CN110086783B (zh) | 一种多账户管理的方法、装置、电子设备及存储介质 | |
| EP3937040B1 (de) | Systeme und verfahren für gesicherten anmeldezugang | |
| EP3127038B1 (de) | Verfahren und system zum schutz und/oder zur anonymisierung einer benutzeridentität und/oder von benutzerdaten eines teilnehmers eines datenschutzdienstes, mobiles kommunikationsnetzwerk, programm und computerprogrammprodukt | |
| AU2017275376B2 (en) | Method and apparatus for issuing a credential for an incident area network | |
| EP3308319B1 (de) | Verfahren und system zur anonymisierung einer benutzeridentität und/oder von benutzerdaten eines teilnehmers eines datenschutzdienstes, programm und computerprogrammprodukt | |
| Gnesi et al. | My data, your data, our data: managing privacy preferences in multiple subjects personal data | |
| US11983284B2 (en) | Consent management methods | |
| AU2014200729A1 (en) | An improved authentication method | |
| EP3017563B1 (de) | Verfahren zum schutz der privatsphäre während des zugriffs auf einen dienst | |
| US9769108B1 (en) | System and method for securing information provided via a social network application | |
| WO2018034192A1 (ja) | 情報処理装置、情報処理方法、及び、記録媒体 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20161031 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R079 Ref document number: 602015051575 Country of ref document: DE Free format text: PREVIOUS MAIN CLASS: G06F0021620000 Ipc: H04W0012020000 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 29/06 20060101ALI20190918BHEP Ipc: G06F 21/62 20130101ALI20190918BHEP Ipc: H04W 12/02 20090101AFI20190918BHEP |
|
| INTG | Intention to grant announced |
Effective date: 20191017 |
|
| GRAS | Grant fee paid |
Free format text: ORIGINAL CODE: EPIDOSNIGR3 |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE PATENT HAS BEEN GRANTED |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: FG4D |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: EP |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: REF Ref document number: 1265151 Country of ref document: AT Kind code of ref document: T Effective date: 20200515 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R096 Ref document number: 602015051575 Country of ref document: DE |
|
| REG | Reference to a national code |
Ref country code: IE Ref legal event code: FG4D |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: MP Effective date: 20200429 |
|
| REG | Reference to a national code |
Ref country code: LT Ref legal event code: MG4D |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: LT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: NO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200729 Ref country code: IS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200829 Ref country code: PT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200831 Ref country code: GR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200730 Ref country code: FI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: MK05 Ref document number: 1265151 Country of ref document: AT Kind code of ref document: T Effective date: 20200429 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: LV Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: HR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: BG Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200729 Ref country code: RS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: AL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| REG | Reference to a national code |
Ref country code: ES Ref legal event code: FG2A Ref document number: 2800900 Country of ref document: ES Kind code of ref document: T3 Effective date: 20210105 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: CZ Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: RO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: AT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: EE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: SM Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: DK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R097 Ref document number: 602015051575 Country of ref document: DE |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
| 26N | No opposition filed |
Effective date: 20210201 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MC Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: PL |
|
| REG | Reference to a national code |
Ref country code: BE Ref legal event code: MM Effective date: 20210331 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: LI Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210331 Ref country code: LU Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210303 Ref country code: CH Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210331 Ref country code: IE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210303 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210331 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: HU Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO Effective date: 20150303 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: CY Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: PL Payment date: 20241213 Year of fee payment: 11 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: FR Payment date: 20241220 Year of fee payment: 11 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20241212 Year of fee payment: 11 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: IT Payment date: 20241216 Year of fee payment: 11 Ref country code: GB Payment date: 20250324 Year of fee payment: 11 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: TR Payment date: 20250102 Year of fee payment: 11 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: ES Payment date: 20250416 Year of fee payment: 11 |